Draft, pending legal review

This page describes how the product actually works and is written by the people who built it. It has not been reviewed by a lawyer and is not yet a binding agreement.

Privacy

The short version: we hold your backups as ciphertext we cannot read, the minimum account data needed to run the service, and analytics you can decline. We do not sell anything to anyone.

What we hold

DataWhyCan we read it?
Backup artifactsThe productNo. Encrypted on your machine with a key we never receive
Artifact metadata: size, checksum, timestamps, retentionListing, retention, billingYes
Account: name, email, workspace membershipSign-in and access controlYes
Source credentials, cloud backups onlyTo connect to the database you asked us toHeld in a secrets vault, read at run time. Local backups never send them
Audit trail: who changed what, and whenYour record, and oursYes. Never contains a secret
Usage countersBillingYes. Quantities only, never content

What we cannot do

Backup data is encrypted before it leaves the machine that produced it, with a public key you supply. We store the result and never receive the private half.

We cannot decrypt your backups. We cannot recover them if you lose your key, and we cannot produce their contents in response to a request from anyone, including a legal one. We can only produce the ciphertext and the metadata listed above.

Who else processes it

We use a small number of providers. Each is listed with what it actually receives.

ProviderPurposeWhat it receives
WorkOSSign-in and organisationsName, email, workspace membership
StripePayments and invoicingBilling details, usage quantities. We never see your card
Amazon S3Artifact storageEncrypted artifacts
Oracle CloudCompute for the serviceRuns the application; holds no plaintext backup data
PostHogTraffic here and in the dashboardPage views and referrers, only if you accept. In the dashboard, a randomly generated account id. Crash reports either way. Never a backup name, hostname or credential
Grafana CloudInfrastructure metricsMachine metrics. No customer data

Analytics and cookies

This site and the dashboard both use PostHog to count visits and to report crashes. One choice covers both, and it is served from our own domain rather than a third-party tracking host. There is no advertising network and no cross-site tracking pixel.

Accept and we count your visits and link them across pages using a cookie. Decline and we set no cookie and store no identifier, so nothing follows you from one page load to the next.

Crashes are reported either way. We cannot fix a bug we never hear about, and a crash report from a visitor who declined carries no cookie and no identifier, so it is not attributed to anyone. It contains the error, where in the code it happened, and which page was open.

We do not record your screen. Session replay is switched off in both the site and the dashboard, so nothing you type or read is captured.

We also use Google Search Console to see which searches lead here. It reports from Google’s own index and receives nothing from us.

How long we keep things

  • Artifacts are kept for as long as the retention policy you set says, then deleted. If you set a protection lock, they cannot be deleted before it expires, including by us.
  • Run history is available for 30 days.
  • Audit entries are kept for the life of the workspace.
  • A closed or unpaid account keeps its data for a year before anything is deleted, and downloads keep working throughout.

Your data, on the way out

You can download every artifact you hold, at any time, in every account state. Artifacts are self-describing and open with standard tools, so leaving does not require our cooperation or our continued existence.

Requests

To see, correct or delete the account data we hold, email us from the address on the account. We will tell you what we hold and what we cannot produce, which for backup contents is everything.